Lab 14 — Wireless Network Configuration and Security
Mission Information
Section titled “Mission Information”| Item | Details |
|---|---|
| Lab | 14 |
| Lab Name | Wireless Network Configuration and Security |
| Track | CompTIA Network+ |
| Difficulty | Intermediate |
| Estimated Time | 120–150 minutes |
| Primary Role | Network Technician / Junior Network Administrator |
| Environment | Network+ Wireless LAN Lab |
| Primary Systems | NETPLUS-WLAN-AP01, NETPLUS-CLIENT01, NETPLUS-RTR01, NETPLUS-SW01 |
| Primary Tools | Wireless AP Console, Router/Switch CLI, Windows/Linux Wireless Tools, Wireshark |
| Skills | Wi-Fi, SSIDs, Bands, Channels, WPA2, WPA3, PSK, 802.1X, RADIUS, Guest WLAN, VLANs, Roaming, Wireless Troubleshooting |
Mission Objective: Design and configure a secure wireless LAN, connect clients, validate addressing and access, apply security controls, separate guest traffic, and troubleshoot common wireless connectivity, interference, authentication, and performance problems.
Mission Scenario
Section titled “Mission Scenario”GHC Enterprise currently relies mainly on wired networking.
The organization now wants wireless connectivity for:
Employees
Mobile Devices
Laptops
GuestsThe network team requests two wireless networks:
GHC-STAFF
GHC-GUESTThe design must ensure that:
Employees ↓Access Internal Resourceswhile:
Guests ↓Internet / External Access OnlyThe network must also use modern wireless security and avoid insecure configurations.
Your mission is to configure:
Wireless Access Point ↓SSIDs ↓Authentication ↓Encryption ↓VLAN Segmentation ↓DHCP ↓Routing ↓Secure Wireless ConnectivityMission Objectives
Section titled “Mission Objectives”By completing this lab, you will be able to:
-
explain wireless LAN architecture
-
understand access points
-
understand SSIDs
-
understand BSS and ESS concepts
-
identify 2.4 GHz, 5 GHz, and 6 GHz characteristics
-
understand wireless channels
-
understand channel overlap
-
understand channel width
-
configure a wireless SSID
-
configure WPA2-Personal
-
understand WPA3-Personal
-
compare PSK and enterprise authentication
-
understand 802.1X
-
understand RADIUS
-
connect wireless clients
-
validate DHCP over wireless
-
configure guest wireless
-
map SSIDs to VLANs
-
understand wireless client isolation
-
understand signal strength and RSSI
-
understand roaming
-
identify rogue AP concepts
-
understand evil twin threats
-
troubleshoot authentication failures
-
troubleshoot poor signal
-
troubleshoot interference
-
troubleshoot DHCP and VLAN problems on WLANs
1. Build the Wireless Lab Topology
Section titled “1. Build the Wireless Lab Topology”Use:
NETPLUS-RTR01 | | NETPLUS-SW01 | | NETPLUS-WLAN-AP01 / \ / \ / \ GHC-STAFF GHC-GUEST | | NETPLUS-CLIENT01 Guest Client2. Define the Wireless Networks
Section titled “2. Define the Wireless Networks”Use:
SSID:GHC-STAFF
Purpose:Employee Wirelessand:
SSID:GHC-GUEST
Purpose:Guest Wireless3. Define the VLAN Design
Section titled “3. Define the VLAN Design”Use:
| SSID | VLAN | Network | Gateway |
|---|---|---|---|
| GHC-STAFF | 10 | 10.10.10.0/24 |
10.10.10.1 |
| GHC-GUEST | 40 | 10.10.40.0/24 |
10.10.40.1 |
This aligns wireless traffic with the VLAN concepts from Lab 07.
4. Understand Wireless LAN Architecture
Section titled “4. Understand Wireless LAN Architecture”A wireless LAN typically contains:
Wireless Client ↓Access Point ↓Wired Ethernet Network ↓Switch ↓Router / ServicesThe access point bridges wireless clients into the wired network.
5. Understand the Access Point
Section titled “5. Understand the Access Point”An:
Access Pointprovides wireless network connectivity to client devices.
Typical responsibilities include:
Advertise SSID
Manage Wireless Associations
Apply WLAN Security
Bridge Wireless Traffic
Map SSID to VLAN
Support Roaming6. Understand SSID
Section titled “6. Understand SSID”SSID stands for:
Service Set IdentifierIt is the wireless network name users see.
Examples:
GHC-STAFF
GHC-GUESTThe SSID identifies the WLAN, but the SSID itself is not a security control.
7. Understand BSS
Section titled “7. Understand BSS”A:
Basic Service Setor:
BSStypically represents:
One Access Point+Associated Wireless ClientsConceptually:
AP01 / | \ / | \ Client Client Client8. Understand BSSID
Section titled “8. Understand BSSID”The:
BSSIDidentifies a specific Basic Service Set.
It is commonly based on a wireless interface MAC address.
Do not confuse:
SSIDwith:
BSSIDSSID:
Wireless Network NameBSSID:
Specific AP Radio / BSS Identifier9. Understand ESS
Section titled “9. Understand ESS”An:
Extended Service Setor:
ESSallows multiple APs to provide the same logical wireless network.
Example:
AP01 AP02 | |GHC-STAFF GHC-STAFF \ / \ / Client RoamingThis supports broader coverage.
10. Understand Wi-Fi Frequency Bands
Section titled “10. Understand Wi-Fi Frequency Bands”Modern WLANs commonly operate in:
2.4 GHz
5 GHz
6 GHzEach band has different characteristics.
11. Understand 2.4 GHz
Section titled “11. Understand 2.4 GHz”2.4 GHz generally provides:
Longer Range
Better Wall Penetrationbut has:
Fewer Non-Overlapping Channels
More Interference
More Competing DevicesCommon interference sources include:
Bluetooth
Microwave Ovens
Other Wi-Fi Networks
IoT Devices12. Understand 5 GHz
Section titled “12. Understand 5 GHz”5 GHz generally offers:
More Channels
Higher Capacity
Less 2.4 GHz Congestionbut often:
Shorter Range
Reduced Wall Penetrationcompared with 2.4 GHz.
13. Understand 6 GHz
Section titled “13. Understand 6 GHz”6 GHz is associated with newer Wi-Fi generations and provides additional spectrum.
Benefits can include:
More Available Channels
Reduced Legacy Interference
Higher CapacityCoverage characteristics depend on environment and device support.
14. Compare Wireless Bands
Section titled “14. Compare Wireless Bands”| Feature | 2.4 GHz | 5 GHz | 6 GHz |
|---|---|---|---|
| Range | Higher | Moderate | Generally lower |
| Congestion | Higher | Lower | Lower |
| Channel availability | Lower | Higher | Higher |
| Legacy support | Very high | High | Newer devices |
| Wall penetration | Better | Moderate | Generally lower |
15. Understand Wireless Channels
Section titled “15. Understand Wireless Channels”Wireless networks divide frequency spectrum into:
ChannelsNearby APs using overlapping channels can interfere with one another.
16. 2.4 GHz Channel Planning
Section titled “16. 2.4 GHz Channel Planning”A common simplified channel plan in many regulatory domains is:
1
6
11because these are commonly treated as non-overlapping 20 MHz channels.
Always follow local regulatory requirements and device capabilities.
17. Understand Co-Channel Interference
Section titled “17. Understand Co-Channel Interference”If nearby APs use the same channel:
AP01Channel 6
AP02Channel 6they share airtime.
This is:
Co-Channel InterferenceIt may reduce performance even when the network remains functional.
18. Understand Adjacent-Channel Interference
Section titled “18. Understand Adjacent-Channel Interference”If APs use overlapping channels:
AP01Channel 4
AP02Channel 6signals can interfere more severely.
This is:
Adjacent-Channel Interference19. Understand Channel Width
Section titled “19. Understand Channel Width”Wi-Fi may use channel widths such as:
20 MHz
40 MHz
80 MHz
160 MHzWider channels can increase throughput potential but consume more spectrum.
In dense environments:
Wider≠Always Better20. Understand Wireless Standards
Section titled “20. Understand Wireless Standards”At Network+ level, be familiar with Wi-Fi generations and the IEEE 802.11 family.
Examples include:
802.11n
802.11ac
802.11axcommonly associated with:
Wi-Fi 4
Wi-Fi 5
Wi-Fi 6Newer variants may extend capabilities into 6 GHz.
21. Connect AP01 to the Switch
Section titled “21. Connect AP01 to the Switch”Connect:
NETPLUS-WLAN-AP01to:
NETPLUS-SW01The switch port may need to carry:
VLAN 10
VLAN 40because AP01 will host both STAFF and GUEST SSIDs.
22. Configure the AP Switch Port as a Trunk
Section titled “22. Configure the AP Switch Port as a Trunk”Cisco-like example:
configure terminal
interface <ap-port> switchport mode trunk switchport trunk allowed vlan 10,40 no shutdown23. Verify the Trunk
Section titled “23. Verify the Trunk”Run:
show interfaces trunkConfirm:
VLAN 10VLAN 40are allowed.
24. Understand SSID-to-VLAN Mapping
Section titled “24. Understand SSID-to-VLAN Mapping”The AP should map:
GHC-STAFF ↓VLAN 10and:
GHC-GUEST ↓VLAN 40This means the wireless network name determines which wired VLAN the client’s traffic enters.
25. Configure VLAN 10 Gateway
Section titled “25. Configure VLAN 10 Gateway”Ensure:
10.10.10.1is available as the gateway for STAFF clients.
26. Configure VLAN 40 Gateway
Section titled “26. Configure VLAN 40 Gateway”Ensure:
10.10.40.1is available as the gateway for GUEST clients.
Use router subinterfaces or Layer 3 SVIs according to your existing lab topology.
27. Configure DHCP for STAFF
Section titled “27. Configure DHCP for STAFF”Provide:
Network:10.10.10.0/24
Pool:10.10.10.100–10.10.10.200
Gateway:10.10.10.1
DNS:<lab DNS server>28. Configure DHCP for GUEST
Section titled “28. Configure DHCP for GUEST”Provide:
Network:10.10.40.0/24
Pool:10.10.40.100–10.10.40.200
Gateway:10.10.40.1
DNS:<approved DNS server>29. Configure the STAFF SSID
Section titled “29. Configure the STAFF SSID”On AP01 create:
SSID:GHC-STAFFMap it to:
VLAN 1030. Choose the STAFF Wireless Band
Section titled “30. Choose the STAFF Wireless Band”For the lab, enable:
5 GHzif supported.
You may also enable:
2.4 GHzto compare behavior.
31. Configure Channel Selection
Section titled “31. Configure Channel Selection”Use either:
Automatic Channel Selectionor select a safe lab channel manually.
For example:
2.4 GHz:Channel 1
5 GHz:Approved available channelExact channels vary by regulatory region and equipment.
32. Understand WLAN Security Modes
Section titled “32. Understand WLAN Security Modes”Common historical and modern modes include:
Open
WEP
WPA
WPA2
WPA3Avoid:
WEPand legacy WPA configurations.
33. Understand WPA2
Section titled “33. Understand WPA2”WPA2 commonly uses:
AES-based CCMPfor secure wireless communication.
For a small WLAN, you may use:
WPA2-Personalwith a:
Pre-Shared Key34. Understand WPA3
Section titled “34. Understand WPA3”WPA3 improves wireless security over WPA2.
WPA3-Personal uses:
SAEinstead of the traditional WPA2-Personal PSK authentication exchange.
Use WPA3 where supported by all required clients and infrastructure.
35. Configure STAFF Security
Section titled “35. Configure STAFF Security”For this lab, configure either:
WPA2-Personalor:
WPA3-Personaldepending on AP/client capabilities.
Use a strong lab passphrase.
Example format:
GHC-Lab-WLAN-2026!Do not reuse real credentials.
36. Understand PSK
Section titled “36. Understand PSK”PSK means:
Pre-Shared KeyThe same wireless secret is shared among authorized users/devices.
This works well for:
Home Networks
Small Offices
Labsbut becomes harder to manage in large enterprise networks.
37. Connect CLIENT01 to STAFF
Section titled “37. Connect CLIENT01 to STAFF”On CLIENT01, view available WLANs.
Windows:
netsh wlan show networksLocate:
GHC-STAFFConnect using the configured lab credentials.
38. Verify Wireless Interface
Section titled “38. Verify Wireless Interface”Run:
netsh wlan show interfacesRecord:
SSID:
BSSID:
Signal:
Radio Type:
Channel:
Receive Rate:
Transmit Rate:39. Verify DHCP Address
Section titled “39. Verify DHCP Address”Run:
ipconfig /allCLIENT01 should receive:
10.10.10.xbecause:
GHC-STAFF ↓VLAN 1040. Verify Gateway Connectivity
Section titled “40. Verify Gateway Connectivity”Run:
ping 10.10.10.1Expected:
Success41. Verify DNS
Section titled “41. Verify DNS”Run:
nslookup server01.gohackerscloud.labif the DNS lab remains configured.
42. Verify Internal Resource Access
Section titled “42. Verify Internal Resource Access”Test:
ping 10.10.10.30or another approved internal resource.
This validates:
Wireless Client ↓SSID ↓VLAN ↓DHCP ↓Routing ↓Internal Resource43. Configure the GUEST SSID
Section titled “43. Configure the GUEST SSID”Create:
SSID:GHC-GUESTMap to:
VLAN 4044. Configure Guest Security
Section titled “44. Configure Guest Security”Depending on lab goals, configure:
WPA2/WPA3-Personalwith a separate guest passphrase.
Do not reuse the STAFF key.
Example:
GHC-Guest-Lab-2026!45. Connect a Guest Client
Section titled “45. Connect a Guest Client”Connect a second wireless client to:
GHC-GUESTVerify it receives:
10.10.40.x46. Verify Guest Gateway
Section titled “46. Verify Guest Gateway”The guest client should use:
10.10.40.1as its gateway.
47. Validate VLAN Separation
Section titled “47. Validate VLAN Separation”STAFF client:
10.10.10.xGuest client:
10.10.40.xThis confirms:
Different SSIDs ↓Different VLANs ↓Different IP Networks48. Restrict Guest Access
Section titled “48. Restrict Guest Access”Guest clients should not have unrestricted access to internal networks.
Conceptually implement:
GUEST VLAN ↓Block Internal RFC1918 / Corporate Networks ↓Allow Required External ServicesUse an ACL or firewall according to your lab topology.
49. Test Guest Isolation from STAFF
Section titled “49. Test Guest Isolation from STAFF”From GUEST client, attempt:
ping 10.10.10.20Expected:
Blockedif policy is configured.
50. Test Guest External Connectivity
Section titled “50. Test Guest External Connectivity”If the lab has a safe external test network, verify the guest client can reach it.
Expected:
Guest ↓Gateway ↓NAT / Routing ↓External Network51. Understand Client Isolation
Section titled “51. Understand Client Isolation”Wireless APs may support:
Client Isolationor:
AP IsolationThis prevents wireless clients on the same SSID from communicating directly with one another.
Useful for:
Guest Networks
Public Wi-Fi52. Enable Guest Client Isolation
Section titled “52. Enable Guest Client Isolation”Where supported, enable isolation on:
GHC-GUESTConnect two guest clients.
Test client-to-client communication.
Expected:
Guest Client A XGuest Client Bdepending on implementation.
53. Understand Signal Strength
Section titled “53. Understand Signal Strength”Wireless quality depends heavily on:
Signal StrengthCommon measurements include:
RSSIand values represented in:
dBm54. Understand dBm
Section titled “54. Understand dBm”Wireless signal strength is often represented using negative numbers.
Conceptually:
-40 dBmVery Strong
-60 dBmGood
-70 dBmWeaker
-80 dBmPoor / UnreliableExact acceptable values depend on application and environment.
Remember:
Closer to Zero=Stronger Signal55. Check Windows Wireless Signal
Section titled “55. Check Windows Wireless Signal”Run:
netsh wlan show interfacesRecord:
Signal:<percentage>Some wireless tools provide more detailed RSSI values.
56. Understand SNR
Section titled “56. Understand SNR”SNR means:
Signal-to-Noise RatioIt compares:
Desired Wireless Signalagainst:
Background NoiseHigher SNR generally means better wireless quality.
57. Understand Interference
Section titled “57. Understand Interference”Wireless interference can result from:
Nearby APs
Bluetooth
Microwave Ovens
Cordless Devices
IoT Equipment
Physical ObstaclesSymptoms can include:
Low Throughput
High Retransmissions
Disconnections
High Latency58. Perform a Wireless Survey
Section titled “58. Perform a Wireless Survey”Using AP or client tools, record:
SSID
BSSID
Band
Channel
Signal Strength
Security Modefor nearby lab WLANs.
Do not collect or analyze unrelated private network traffic.
59. Build a Wireless Survey Table
Section titled “59. Build a Wireless Survey Table”| SSID | Band | Channel | Signal | Security |
|---|---|---|---|---|
| GHC-STAFF | 5 GHz | <channel> |
<signal> |
WPA2/WPA3 |
| GHC-GUEST | 5 GHz | <channel> |
<signal> |
WPA2/WPA3 |
60. Troubleshooting Scenario 1 — Wrong Password
Section titled “60. Troubleshooting Scenario 1 — Wrong Password”Change or intentionally enter an incorrect STAFF passphrase.
Expected:
SSID Visible ↓Connection Attempt ↓Authentication Failure61. Diagnose Wrong Wireless Credentials
Section titled “61. Diagnose Wrong Wireless Credentials”Check:
Correct SSID?
Correct Security Mode?
Correct Passphrase?
Saved Profile Stale?The presence of the SSID proves only that the AP is advertising.
62. Remove a Saved Windows WLAN Profile
Section titled “62. Remove a Saved Windows WLAN Profile”If needed:
netsh wlan delete profile name="GHC-STAFF"Reconnect with the correct settings.
63. Troubleshooting Scenario 2 — SSID Not Visible
Section titled “63. Troubleshooting Scenario 2 — SSID Not Visible”Disable SSID broadcasting or the WLAN temporarily.
The client may no longer see:
GHC-STAFFInvestigate:
AP Powered On?
WLAN Enabled?
SSID Configured?
Radio Enabled?
Supported Band?
Client Radio Enabled?64. Hidden SSIDs
Section titled “64. Hidden SSIDs”Disabling SSID advertisement does not provide strong wireless security.
A hidden SSID should not be treated as a substitute for:
WPA2/WPA3
Strong Authentication65. Troubleshooting Scenario 3 — Unsupported Band
Section titled “65. Troubleshooting Scenario 3 — Unsupported Band”Configure STAFF as:
6 GHz Onlywhile using a client that supports only:
2.4 / 5 GHzExpected:
Client Cannot Discover / Join WLANRoot cause:
Radio Capability Mismatch66. Troubleshooting Scenario 4 — Weak Signal
Section titled “66. Troubleshooting Scenario 4 — Weak Signal”Move the client farther away from AP01 or reduce lab radio power where supported.
Observe:
Signal Strength DecreasesPotential symptoms:
Lower Throughput
Higher Latency
Packet Loss
Disconnection67. Diagnose Weak Signal
Section titled “67. Diagnose Weak Signal”Investigate:
Distance
Walls
Metal Objects
AP Placement
Transmit Power
Antenna Orientation
Interference68. Troubleshooting Scenario 5 — Channel Interference
Section titled “68. Troubleshooting Scenario 5 — Channel Interference”Configure two nearby lab AP radios onto the same or overlapping 2.4 GHz channels.
Observe performance.
Compare with a planned channel layout.
The goal is to understand:
Channel Planning ↓Less Interference ↓Better Airtime Efficiency69. Troubleshooting Scenario 6 — WLAN Connected but No IP
Section titled “69. Troubleshooting Scenario 6 — WLAN Connected but No IP”CLIENT01 successfully joins:
GHC-STAFFbut receives:
169.254.x.xThis indicates:
Wireless Association:Working
DHCP:Failing70. Diagnose WLAN DHCP Failure
Section titled “70. Diagnose WLAN DHCP Failure”Check:
SSID-to-VLAN Mapping
AP Trunk
VLAN Allowed?
DHCP Scope?
DHCP Relay?
DHCP Server Reachable?This demonstrates why wireless troubleshooting must extend beyond radio connectivity.
71. Troubleshooting Scenario 7 — Wrong VLAN Mapping
Section titled “71. Troubleshooting Scenario 7 — Wrong VLAN Mapping”Map:
GHC-STAFFaccidentally to:
VLAN 40CLIENT01 may receive:
10.10.40.xinstead of:
10.10.10.x72. Diagnose Wrong SSID VLAN
Section titled “72. Diagnose Wrong SSID VLAN”Check:
SSID:GHC-STAFF
Mapped VLAN:40Expected:
10Correct the AP WLAN mapping.
73. Troubleshooting Scenario 8 — VLAN Missing on AP Trunk
Section titled “73. Troubleshooting Scenario 8 — VLAN Missing on AP Trunk”Remove:
VLAN 40from the switch trunk toward AP01.
STAFF may still work.
GUEST may fail.
This gives a useful symptom:
One SSID Works
One SSID Fails74. Diagnose Missing Trunk VLAN
Section titled “74. Diagnose Missing Trunk VLAN”Check:
show interfaces trunkVerify:
VLAN 10:Allowed
VLAN 40:MissingRestore VLAN 40.
75. Troubleshooting Scenario 9 — Wrong Guest Gateway
Section titled “75. Troubleshooting Scenario 9 — Wrong Guest Gateway”DHCP gives guest clients:
Gateway:10.10.10.1instead of:
10.10.40.1Guest clients may communicate locally but fail to route correctly.
Correct the DHCP scope option.
76. Troubleshooting Scenario 10 — DNS Failure over WLAN
Section titled “76. Troubleshooting Scenario 10 — DNS Failure over WLAN”Wireless connectivity works.
Gateway ping works.
IP-based access works.
Hostname resolution fails.
Check:
DHCP DNS Option
DNS Server Reachability
DNS Service
FirewallThe wireless layer may be healthy.
77. Understand Wireless Roaming
Section titled “77. Understand Wireless Roaming”In an ESS, a client may move between APs that advertise the same SSID.
Conceptually:
AP01GHC-STAFF ↓Client Moves ↓AP02GHC-STAFFThis is:
Roaming78. Build a Two-AP Roaming Lab
Section titled “78. Build a Two-AP Roaming Lab”Add:
NETPLUS-WLAN-AP02Configure:
SSID:GHC-STAFFwith compatible security and VLAN settings.
Use a different appropriate channel.
79. Why Different Channels Matter
Section titled “79. Why Different Channels Matter”Adjacent APs should generally avoid unnecessary channel overlap.
Example:
AP01Channel 1
AP02Channel 6for a simplified 2.4 GHz deployment.
80. Test Roaming
Section titled “80. Test Roaming”Move the client logically or physically between coverage areas.
Observe the client’s:
BSSIDbefore and after.
The:
SSIDmay remain:
GHC-STAFFwhile the:
BSSIDchanges.
81. Understand Roaming Decision
Section titled “81. Understand Roaming Decision”In many WLANs, the:
Clientplays a major role in deciding when to roam.
Factors can include:
Signal Strength
Driver Behavior
AP Capability
Roaming Assistance Features82. Understand 802.1X
Section titled “82. Understand 802.1X”Enterprise WLANs may use:
802.1Xfor centralized authentication.
Conceptually:
Wireless Client ↓Access Point ↓RADIUS Server ↓Identity Validation83. Understand the 802.1X Roles
Section titled “83. Understand the 802.1X Roles”Common terminology:
Supplicant=ClientAuthenticator=Access Point / SwitchAuthentication Server=RADIUS Server84. Understand RADIUS
Section titled “84. Understand RADIUS”RADIUS provides centralized:
Authentication
Authorization
Accountingoften remembered as:
AAA85. WPA2/WPA3 Enterprise
Section titled “85. WPA2/WPA3 Enterprise”Enterprise wireless security can use:
WPA2-Enterpriseor:
WPA3-Enterprisewith:
802.1X+RADIUSinstead of one shared PSK.
86. Compare Personal and Enterprise WLAN Security
Section titled “86. Compare Personal and Enterprise WLAN Security”| Feature | Personal | Enterprise |
|---|---|---|
| Authentication | Shared secret | Individual identity |
| Backend | None required | RADIUS/AAA |
| User revocation | Change PSK or device-specific mechanisms | Disable identity |
| Scalability | Small networks | Enterprise |
| Accountability | Lower | Higher |
87. Enterprise Authentication Flow
Section titled “87. Enterprise Authentication Flow”Conceptually:
CLIENT ↓Join GHC-STAFF ↓AP requests authentication ↓802.1X exchange ↓RADIUS ↓Identity validated ↓Network access granted88. Understand EAP
Section titled “88. Understand EAP”802.1X commonly uses:
EAPor:
Extensible Authentication ProtocolDifferent EAP methods provide different authentication approaches.
For Network+, understand the role of EAP rather than implementing every method.
89. Understand Rogue Access Points
Section titled “89. Understand Rogue Access Points”A:
Rogue Access Pointis an unauthorized AP connected to or operating within an organization’s environment.
Examples:
Employee Installs Personal AP
Unauthorized Wireless Router
Misconfigured DevicePossible risks include:
Security Policy Bypass
Unauthorized Network Access
Traffic Exposure90. Understand Evil Twin
Section titled “90. Understand Evil Twin”An:
Evil Twinis a malicious or unauthorized wireless network designed to imitate a legitimate WLAN.
Example:
Legitimate:GHC-STAFF
Malicious:GHC-STAFFUsers may connect to the wrong AP.
91. Defensive Wireless Validation
Section titled “91. Defensive Wireless Validation”When investigating suspicious wireless networks, compare:
SSID
BSSID
Security Mode
Channel
Signal Characteristics
Authorized AP InventoryDo not assume identical SSID means identical infrastructure.
92. Understand Deauthentication Attacks Conceptually
Section titled “92. Understand Deauthentication Attacks Conceptually”Wireless management frames can be abused in some environments to disrupt client connectivity.
Modern protections such as:
Protected Management Framescan reduce certain management-frame attacks.
This lab focuses on defensive awareness, not performing disruptive attacks.
93. Understand Protected Management Frames
Section titled “93. Understand Protected Management Frames”PMF helps protect certain wireless management communications.
It is associated with modern Wi-Fi security and is important in WPA3 deployments.
94. Understand Captive Portals
Section titled “94. Understand Captive Portals”Guest WLANs may use a:
Captive Portalto present:
Terms of Use
Login Page
Guest Registrationbefore allowing external access.
A captive portal is not a substitute for proper wireless encryption and segmentation.
95. Understand AP Placement
Section titled “95. Understand AP Placement”Poor AP placement can create:
Coverage Gaps
Dead Zones
Excessive Overlap
InterferenceBetter design considers:
Building Layout
User Density
Walls
Interference
Capacity
Roaming96. Coverage vs Capacity
Section titled “96. Coverage vs Capacity”Wireless design must consider both:
Can the client hear the AP?and:
Can the AP handle the number of clients?Good signal does not automatically mean good performance.
97. Understand Airtime
Section titled “97. Understand Airtime”Wireless is a shared medium.
Clients attached to the same radio compete for:
AirtimeA slow or distant client may consume more airtime for the same amount of data.
98. Wireless Troubleshooting Methodology
Section titled “98. Wireless Troubleshooting Methodology”Use:
Is Wireless Adapter Enabled? ↓Can Client See SSID? ↓Does Client Support Band? ↓Correct Security Mode? ↓Correct Credentials? ↓Association Successful? ↓Correct VLAN? ↓DHCP Lease Obtained? ↓Correct Gateway? ↓DNS Working? ↓Signal Strong Enough? ↓Channel Interference? ↓Routing / Firewall Correct? ↓Application Working?99. Mission Challenge — Identify the Band
Section titled “99. Mission Challenge — Identify the Band”Requirement:
Maximum compatibility+Longer indoor reachLikely preference:
2.4 GHzwith the tradeoff of more congestion.
100. Mission Challenge — Higher Capacity
Section titled “100. Mission Challenge — Higher Capacity”Requirement:
More channels+Less 2.4 GHz congestionLikely preference:
5 GHzor 6 GHz where appropriate and supported.
101. Mission Challenge — Wrong IP Network
Section titled “101. Mission Challenge — Wrong IP Network”Client joins:
GHC-STAFFbut receives:
10.10.40.120Expected:
10.10.10.xFirst investigate:
SSID-to-VLAN Mapping102. Mission Challenge — AP Visible but Connection Fails
Section titled “102. Mission Challenge — AP Visible but Connection Fails”Symptoms:
SSID Visible
Strong Signal
Authentication FailureInvestigate:
Passphrase
Security Mode
Client Compatibility
Saved Profile103. Mission Challenge — Client Connected but APIPA
Section titled “103. Mission Challenge — Client Connected but APIPA”Client shows:
Connected to GHC-STAFFbut:
169.254.35.10Investigate:
VLAN
DHCP
Trunk
Relaynot the wireless password.
104. Mission Challenge — Guest Reaches Internal Server
Section titled “104. Mission Challenge — Guest Reaches Internal Server”Guest client:
10.10.40.120can reach:
10.10.10.30but policy says guests must not access internal resources.
The wireless association is working.
The problem is:
Segmentation / Firewall / ACL Policy105. Mission Challenge — Same SSID, Different AP
Section titled “105. Mission Challenge — Same SSID, Different AP”Client originally connected to:
SSID:GHC-STAFF
BSSID:AA:AA:AA:AA:AA:01Later:
SSID:GHC-STAFF
BSSID:AA:AA:AA:AA:AA:02This can indicate:
Client Roamed to Another AP106. Mission Challenge — Rogue WLAN
Section titled “106. Mission Challenge — Rogue WLAN”Authorized AP inventory contains:
GHC-STAFFBSSID:AA:AA:AA:AA:AA:01but a nearby WLAN appears as:
GHC-STAFFBSSID:BB:BB:BB:BB:BB:99Investigate as:
Potential Rogue / Evil Twinrather than trusting the SSID name alone.
107. Create the Lab Workspace
Section titled “107. Create the Lab Workspace”On NETPLUS-ADMIN:
mkdir -p ~/NetworkPlus-Labs/LAB14/{Captures,Screenshots,Configs,Notes}Create:
touch ~/NetworkPlus-Labs/LAB14/Notes/lab14-notes.md108. Save Wireless Configuration Evidence
Section titled “108. Save Wireless Configuration Evidence”Document:
AP Name
SSID
BSSID
Band
Channel
Channel Width
Security Mode
VLAN Mapping
Guest Isolation
Transmit PowerStore under:
~/NetworkPlus-Labs/LAB14/Configs/109. Document Your Findings
Section titled “109. Document Your Findings”Use:
# LAB14 — Wireless Network Configuration and Security
## Wireless Infrastructure
AP:NETPLUS-WLAN-AP01
Management IP:
Switch Port:
Trunk VLANs:
## STAFF WLAN
SSID:GHC-STAFF
VLAN:10
Network:10.10.10.0/24
Gateway:10.10.10.1
Security:
Band:
Channel:
Channel Width:
## GUEST WLAN
SSID:GHC-GUEST
VLAN:40
Network:10.10.40.0/24
Gateway:10.10.40.1
Security:
Client Isolation:Enabled / Disabled
## STAFF Client
IP:
Gateway:
DNS:
SSID:
BSSID:
Signal:
Channel:
## Guest Client
IP:
Gateway:
DNS:
SSID:
BSSID:
Internal Access:Allowed / Blocked
External Access:Pass / Fail
## Wireless Survey
SSID:
BSSID:
Band:
Channel:
Signal:
Security:
## Troubleshooting
### Wrong Passphrase
Symptom:
Root Cause:
Fix:
### SSID Not Visible
Symptom:
Root Cause:
Fix:
### Weak Signal
Symptom:
Root Cause:
Fix:
### DHCP Failure
Symptom:
Root Cause:
Fix:
### Wrong VLAN
Symptom:
Root Cause:
Fix:
### Missing Trunk VLAN
Symptom:
Root Cause:
Fix:
### DNS Failure
Symptom:
Root Cause:
Fix:
## Roaming
Original AP/BSSID:
New AP/BSSID:
SSID:
Connectivity Impact:
## Security Assessment
PSK / Enterprise:
Guest Segmentation:
Client Isolation:
Rogue AP Findings:
## Final Assessment
Summarize how the WLAN was secured, segmented, validated, and troubleshot.110. Evidence to Capture
Section titled “110. Evidence to Capture”Capture:
01-wireless-topology.png
02-ap-switch-trunk.png
03-staff-ssid-config.png
04-staff-security-config.png
05-staff-vlan-mapping.png
06-guest-ssid-config.png
07-guest-security-config.png
08-guest-vlan-mapping.png
09-client-visible-networks.png
10-client-staff-connection.png
11-wireless-interface-details.png
12-staff-dhcp-lease.png
13-staff-gateway-test.png
14-staff-internal-access.png
15-guest-dhcp-lease.png
16-guest-gateway-test.png
17-guest-internal-block.png
18-guest-external-access.png
19-client-isolation.png
20-wireless-survey.png
21-channel-information.png
22-signal-strength.png
23-wrong-password.png
24-hidden-ssid.png
25-band-mismatch.png
26-weak-signal.png
27-channel-interference.png
28-wireless-apipa.png
29-wrong-ssid-vlan.png
30-missing-ap-trunk-vlan.png
31-wrong-guest-gateway.png
32-wireless-dns-failure.png
33-ap02-roaming.png
34-bssid-change.png
35-enterprise-authentication-diagram.png
36-final-wireless-topology.png111. Validation Checklist
Section titled “111. Validation Checklist”Infrastructure
Section titled “Infrastructure”-
AP01 connected to switch
-
AP switch port configured correctly
-
VLAN 10 allowed
-
VLAN 40 allowed
-
VLAN gateways available
-
DHCP scopes available
Wireless Fundamentals
Section titled “Wireless Fundamentals”-
AP role understood
-
SSID understood
-
BSS understood
-
BSSID understood
-
ESS understood
-
2.4 GHz understood
-
5 GHz understood
-
6 GHz understood
-
Channel concepts understood
-
Channel width understood
STAFF WLAN
Section titled “STAFF WLAN”-
GHC-STAFF created
-
VLAN 10 mapped
-
WPA2/WPA3 configured
-
STAFF client connected
-
Correct DHCP lease received
-
Gateway verified
-
DNS verified
-
Internal resource access verified
GUEST WLAN
Section titled “GUEST WLAN”-
GHC-GUEST created
-
VLAN 40 mapped
-
Separate credentials configured
-
Guest client connected
-
Correct DHCP lease received
-
Guest gateway verified
-
Internal access restricted
-
External access verified where available
-
Client isolation tested
Wireless Security
Section titled “Wireless Security”-
WEP recognized as insecure
-
WPA2 understood
-
WPA3 understood
-
PSK understood
-
Personal vs Enterprise compared
-
802.1X understood
-
RADIUS understood
-
EAP understood conceptually
-
Rogue AP concept understood
-
Evil twin concept understood
-
PMF concept understood
Wireless Performance
Section titled “Wireless Performance”-
Signal strength reviewed
-
RSSI concept understood
-
dBm understood
-
SNR understood
-
Interference understood
-
Channel planning understood
-
Co-channel interference understood
-
Adjacent-channel interference understood
-
Coverage vs capacity understood
-
Airtime understood
Roaming
Section titled “Roaming”-
AP02 configured where supported
-
Same SSID configured
-
Different appropriate channel used
-
Client roaming observed
-
BSSID change identified
Troubleshooting
Section titled “Troubleshooting”-
Wrong passphrase investigated
-
SSID-not-visible scenario investigated
-
Band incompatibility understood
-
Weak-signal scenario investigated
-
Interference scenario investigated
-
Wireless APIPA scenario investigated
-
Wrong VLAN mapping investigated
-
Missing trunk VLAN investigated
-
Wrong gateway investigated
-
DNS failure distinguished from wireless failure
-
Guest policy failure investigated
Documentation
Section titled “Documentation”-
Wireless topology documented
-
SSIDs documented
-
VLAN mappings documented
-
Security modes documented
-
Survey results recorded
-
Troubleshooting findings documented
-
Screenshots captured
-
Lab notes completed
112. Mission Review
Section titled “112. Mission Review”In this mission, you extended the enterprise network from:
Wired Ethernetto:
Wired+WirelessThe STAFF connection flow became:
Wireless Client ↓GHC-STAFF ↓WPA2 / WPA3 Authentication ↓AP01 ↓VLAN 10 ↓DHCP ↓10.10.10.x ↓Gateway ↓Internal / External NetworkThe GUEST workflow became:
Guest Client ↓GHC-GUEST ↓VLAN 40 ↓10.10.40.x ↓Guest Security Policy ├── X Internal Network └── External AccessYou also learned that a successful wireless connection depends on multiple layers:
Radio ↓SSID ↓Authentication ↓Association ↓VLAN ↓DHCP ↓Routing ↓DNS ↓Firewall ↓ApplicationThe key lesson is:
Wireless troubleshooting should not stop at signal strength. A client must successfully discover the WLAN, authenticate, associate, enter the correct VLAN, receive valid IP configuration, reach its gateway, resolve names, and pass the required network security policies.
Skills Developed
Section titled “Skills Developed”After completing this mission, you should be able to:
-
explain wireless LAN architecture
-
distinguish SSID and BSSID
-
explain BSS and ESS
-
compare 2.4 GHz, 5 GHz, and 6 GHz
-
explain channel planning
-
understand channel width
-
identify wireless interference
-
configure wireless SSIDs
-
configure WPA2/WPA3 security
-
understand PSK authentication
-
explain enterprise wireless authentication
-
explain 802.1X and RADIUS
-
map WLANs to VLANs
-
configure guest wireless segmentation
-
understand client isolation
-
validate wireless DHCP
-
interpret wireless client status
-
understand RSSI and dBm
-
understand roaming
-
recognize rogue APs
-
recognize evil twin concepts
-
troubleshoot authentication failures
-
troubleshoot weak signal
-
troubleshoot WLAN VLAN problems
-
troubleshoot DHCP and DNS over wireless
What’s Next?
Section titled “What’s Next?”Lab 15 — Network Services and Common Protocol Investigation
Section titled “Lab 15 — Network Services and Common Protocol Investigation”You have now built:
Switching ↓VLANs ↓Routing ↓DHCP ↓DNS ↓NAT ↓WirelessThe next mission focuses on the network services that run across this infrastructure.
You will investigate:
-
TCP and UDP
-
well-known ports
-
HTTP and HTTPS
-
SSH
-
FTP and SFTP
-
SMTP
-
DNS
-
DHCP
-
NTP
-
SNMP
-
SMB
-
RDP
-
LDAP and LDAPS
-
service listeners
-
TCP handshakes
-
port connectivity
-
protocol identification
-
encrypted vs unencrypted services
-
packet analysis
-
service troubleshooting
The progression becomes:
Network Infrastructure ↓IP Connectivity ↓Transport Protocol ↓TCP / UDP Port ↓Network Service ↓Application➡️ Next: Lab 15 — Network Services and Common Protocol Investigation